Unauthenticated Access in Faronics Insight Teacher Console
CVE-2023-28344

7.1HIGH

Key Information:

Vendor

Faronics

Status
Vendor
CVE Published:
31 May 2023

What is CVE-2023-28344?

In Faronics Insight version 10.0.19045, a vulnerability has been identified that allows unauthorized attackers to access real-time screenshots of student desktops through the Teacher Console application. This breach enables the viewing of sensitive information without the student’s consent, exposing personal data. Furthermore, attackers can impersonate students by submitting altered screenshots, concealing the actual desktop content from educators. This dual exploit jeopardizes both student privacy and the integrity of the educational environment.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-28344 : Unauthenticated Access in Faronics Insight Teacher Console